Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
271 results
BadKernel preview

BadKernel

GitHubsecmob/badkernel

Full exploit of CVE-2016-6754(BadKernel) and slide of SyScan360 2016

binary-exploitationexploitationpayload-development+3
151
9 years ago
Invoke-PSObfuscation preview

Invoke-PSObfuscation

GitHubgh0x0st/invoke-psobfuscation

An in-depth approach to obfuscating the individual components of a PowerShell payload whether you're on Windows or Kali Linux.

exploitationpayload-developmentpayload-generation+2
2854 years ago
RustyWater-ShellCode-Dropper preview

RustyWater-ShellCode-Dropper

GitHubs3n4t0r-0x0/rustywater-shellcode-dropper

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

binary-exploitationcommand-and-controlexploitation+9
1061 month ago
DuplexSpyCS preview

DuplexSpyCS

GitHubiss4cf0ng/duplexspycs

An open-source, C#-based remote administration tool (RAT), enabling complete control of a remote Windows machine, designed for legitimate remote…

command-and-controleducationpayload-development+5
2226 months ago
ntqueueapcthreadex-ntdll-gadget-injection preview

ntqueueapcthreadex-ntdll-gadget-injection

GitHublloydlabs/ntqueueapcthreadex-ntdll-gadget-injection

This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can…

adversarial-attackids-ips-evasionpayload-development+3
2683 years ago
ds3-nrssr-rce preview

ds3-nrssr-rce

GitHubtremwil/ds3-nrssr-rce

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

binary-exploitationeducationexploitation+8
1694 years ago
DynamicDotNet preview

DynamicDotNet

GitHubbohops/dynamicdotnet

A collection of various and sundry code snippets that leverage .NET dynamic tradecraft

curated-resourceseducationmalware-analysis+4
1452 years ago
Cobaltstrike_BOFLoader preview

Cobaltstrike_BOFLoader

GitHubcodextf2/cobaltstrike_bofloader

open source port/reimplementation of the Cobalt Strike BOF Loader as is

binary-exploitationexploit-frameworkspayload-development+3
746 months ago
EATGuard preview

EATGuard

GitHubconnormcgarr/eatguard

Implementation of an export address table protection mitigation, like Export Address Filtering (EAF)

binary-exploitationdefensive-toolsshellcode
1143 years ago
Pokemon-Shellcode-Loader preview

Pokemon-Shellcode-Loader

GitHubtechryptic/pokemon-shellcode-loader

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

adversarial-attackpayload-developmentpayload-generation+3
1284 years ago
Exploits preview

Exploits

GitHubforrest-orr/exploits

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

binary-exploitationexploitationpayload-development+3
1214 years ago
SharpWhispers preview

SharpWhispers

GitHubsecforce/sharpwhispers

C# porting of SysWhispers2. It uses SharpASM to find the code caves for executing the system call stub.

ids-ips-evasionpayload-developmentpost-exploitation+2
1123 years ago
NullGate preview

NullGate

GitHub0xsch1zo/nullgate

Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.

adversarial-attackencryption-decryption-toolspayload-development+3
1681 year ago
DoubleStar preview

DoubleStar

GitHubforrest-orr/doublestar

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

binary-exploitationexploitationpayload-development+4
1474 years ago
Remote-BOF-Runner preview

Remote-BOF-Runner

GitHubpard0p/remote-bof-runner

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

binary-exploitationcommand-and-controleducation+8
1028 months ago
OneDriveUpdaterSideloading preview

OneDriveUpdaterSideloading

GitHubchoisg/onedriveupdatersideloading

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

adversarial-attackpayload-developmentred-teaming+1
1023 years ago
shellcode preview

shellcode

GitHub0xdea/shellcode

A collection of my shellcode samples.

binary-exploitationeducationexploitation+3
271 month ago
msf_shellcode_analysis preview

msf_shellcode_analysis

GitHubyo-yo-yo-jbo/msf_shellcode_analysis

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

binary-analysiseducationmalware-analysis+3
291 month ago
Previous1…567…16Next